← Back to CVE List
Vulnerability Intelligence Report
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

CVE-2026-64645

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11.

No Active Exploit Signals
CVSS Base Score
8.3
HIGH
EPSS Probability:1.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-918 ↗CWE-918: Server-Side Request Forgery (SSRF)
CWE-601 ↗CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Affected Products & Versions

Vendor Product Affected Versions
vercel next.js >= 12.0.0 < 15.5.21 (affected), >= 16.0.0, < 16.2.11 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.020%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-07-20T17:11:30
Published2026-07-27T17:37:07
Last Updated2026-07-28T14:02:21

LINK COPIED TO CLIPBOARD